Skip to content

build(deps): Bump agent-assembly from 0.0.1rc6 to 0.0.1rc7 in /python/langgraph - #584

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python/langgraph/agent-assembly-0.0.1rc7
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python/langgraph/agent-assembly-0.0.1rc7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps agent-assembly from 0.0.1rc6 to 0.0.1rc7.

Release notes

Sourced from agent-assembly's releases.

v0.0.1-rc.7

python-sdk agent-assembly==0.0.1rc7 — coordinated with agent-assembly v0.0.1-rc.7.

Commits
  • 2b85866 Merge pull request #338 from ai-agent-assembly/bot/aa-ffi-pin-v0.0.1-rc.7
  • 8b58b73 🤖 (aa-ffi-python): Bump aa-core/aa-proto/aa-sdk-client pin to v0.0.1-rc.7
  • 60f3be6 Merge pull request #337 from ai-agent-assembly/dependabot/github_actions/astr...
  • b1b3a12 ⬆ Bump astral-sh/setup-uv from 10.0.1 to 10.1.0
  • 39ac7e0 Merge pull request #333 from ai-agent-assembly/horo-983/consume-shared-engine...
  • 0eec014 ✨ (skills): Consume shared Horonom engineering capabilities (HORO-983)
  • 456e8d5 Merge pull request #332 from ai-agent-assembly/dependabot/uv/gitpython-3.1.59
  • 11a551d Bump gitpython from 3.1.58 to 3.1.59
  • 82aa3c0 Merge pull request #330 from ai-agent-assembly/dependabot/uv/httpx2-2.12.0
  • 834a9a2 Bump httpx2 from 2.5.0 to 2.12.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [agent-assembly](https://github.com/ai-agent-assembly/python-sdk) from 0.0.1rc6 to 0.0.1rc7.
- [Release notes](https://github.com/ai-agent-assembly/python-sdk/releases)
- [Commits](ai-agent-assembly/python-sdk@v0.0.1-rc.6...v0.0.1-rc.7)

---
updated-dependencies:
- dependency-name: agent-assembly
  dependency-version: 0.0.1rc7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: python. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 21, 2026
@dependabot
dependabot Bot requested a review from Chisanan232 as a code owner September 21, 2026 05:12
@sonarqubecloud

Copy link
Copy Markdown

@Chisanan232

Chisanan232 commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Classification: HELD — superseded by #613, blocked upstream by AAASM-6155

Re-examined during the 2026-09-25/26 dependency and security sweep. This PR is left open and unmodified: no relock was pushed to it, no pin was changed, no check was disabled. Recording why here, because until now nothing on this PR said why it is stuck.

Why it is red — both causes measured on this PR, not inferred

1. metadata drift. python/langgraph/pyproject.toml is a generated file. Its source of truth is metadata/sdk-versions.yaml, rendered by scripts/generate_example_metadata.py. That source still pins rc6, so the drift job regenerates the manifest and undoes this PR's edit:

diff --git a/python/langgraph/pyproject.toml b/python/langgraph/pyproject.toml
-    "agent-assembly==0.0.1rc7",
+    "agent-assembly==0.0.1rc6",
Generated example metadata or quick-start snippets are out of sync.

Bumping the generated manifest can never go green. The edit has to land in metadata/sdk-versions.yaml.

2. langgraph, step 4 Install dependencies. Dependabot changed pyproject.toml only and left python/langgraph/uv.lock at rc6, so uv sync --extra dev --locked --no-build refuses:

error: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided.
hint: To update the lockfile, run `uv lock`.

Verified individually on all 18 of these Python PRs: same step, same error, no other failure mode among them.

Why it is not fixed in place

Correcting cause 1 means editing the single shared source of truth, which moves every example at once — so the fix is inherently one pull request, not 18. That pull request already exists: #613 ([AAASM-6154]), which edits metadata/sdk-versions.yaml plus all regenerated manifests and lockfiles. Pushing a relock here instead would either be reverted by the drift job or duplicate #613 and conflict with it.

#613 is itself held, and not on anything this sweep can fix. The examples need AAASM-6155 — an sdk-only registration failure must not be fatal. That fix reached python-sdk main on 2026-09-22, five days after 0.0.1rc7 was uploaded to PyPI on 2026-09-17, so rc7 cannot contain it. See the classification comment on #613 for the container-verified evidence.

Clearing this therefore needs agent-assembly 0.0.1rc8 published. Publishing is a release action and is explicitly out of scope for a dependency sweep — it is @Chisanan232's decision, not something this sweep will trigger. No tag, no release, no prerelease was created.

Disposition

Open and untouched, pending that decision. When rc8 ships, #613 moves the source of truth once and Dependabot should close this PR as superseded; it does not need to be merged.

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Looks like agent-assembly is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/python/langgraph/agent-assembly-0.0.1rc7 branch September 28, 2026 07:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant